Description
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
Published: 2026-09-18
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure (guest VM credentials) by local attacker.
Action: Patch
AI Analysis

Impact

A flaw in cockpit-machines allows a local attacker who can inspect running processes to see guest virtual machine credentials, such as rootPassword and userPassword, that are passed as a JSON argument during VM creation or installation. The exposure lasts only while the installation workflow runs and depends on the host’s process‑visibility permissions, but it enables an attacker to obtain credentials for the VM while the installation is active.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 9 and RHEL 10 systems that run cockpit-machines. No specific minor or patch level is listed, so any version of cockpit-machines installed on those RHEL releases may be vulnerable.

Risk and Exploitability

The CVSS score is 5, indicating moderate severity. No EPSS score is available and the vulnerability is not in CISA’s KEV catalog. The likely attack vector is a local attacker who can view processes; such an attacker can read the process command line to retrieve the exposed credentials. Because the exposure is temporary and requires prior installation activity, the window of opportunity is limited, but the impact includes compromise of VM authentication data.

Generated by OpenCVE AI on September 19, 2026 at 11:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any applicable Red Hat security update that fixes cockpit‑machines.
  • Restrict local user privileges so that only authorized users can view running processes and invoke install_machine.py.
  • When creating or installing a VM, avoid passing credentials via JSON command‑line arguments; use secure credential storage or environment variables instead.
  • Monitor process creation for install_machine.py to detect suspicious credential exposure events.

Generated by OpenCVE AI on September 19, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
Title Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-214
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T18:56:32.197Z

Reserved: 2026-09-16T18:50:18.131Z

Link: CVE-2026-92747

cve-icon Vulnrichment

Updated: 2026-09-18T18:02:35.935Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:18:16.547

Modified: 2026-09-18T23:16:33.163

Link: CVE-2026-92747

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T16:35:00Z

Links: CVE-2026-92747 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:59Z

Weaknesses
  • CWE-214

    Invocation of Process Using Visible Sensitive Information